WEBSITESfor Normal People2026

Part I: Setup (the boring bit that makes it work)05

Chapter 05Step 4

Step 4: One key from you, and full access

2 min read, 2 things to tick

One key from you. I make the rest.

You make one key. The agent makes the rest.

"Shouldn't I give the agent as little access as possible?"

In a company with 200 engineers, yes. For your own bakery site, no.

Every permission you leave out is a moment later where the agent stops, says "I don't have access to do that", and sends you into a dashboard to find the checkbox it meant. That's the exact thing this guide exists to kill.

So the agent gets broad access to your own accounts, and the keys get protected properly instead: they live in the vault, never in chat, never in code, and they expire on their own.

The Cloudflare bootstrap key

Instead of you building a token with fifteen permission rows (it's miserable, I've done it enough times), you make a small key whose only job is to let the agent create its own full-access token.

  1. Cloudflare dashboard → profile icon (top right) → Profile → API Tokens → Create Token.
  2. Find the Create Additional Tokens template → Use template.
  3. TTL: set an end date one week out. The agent only needs it once. After that it has its own token.
  4. Continue to summary → Create Token. Copy it.
  5. Bitwarden → Secrets Manager → websites project → New secret. Name: CLOUDFLARE_BOOTSTRAP_TOKEN. Value: paste. Save.

That's the whole chapter's clicking.

Watch itCloudflare profile → API Tokens → Create Additional Tokens template → create → paste into Bitwarden. Under a minute.

Personal details are blurred. Press play, it's silent and loops.

In chapter 6 the agent uses this to create CLOUDFLARE_API_TOKEN: one token with edit access to Workers, DNS, the database, file storage, email, spam protection and everything else a site needs, across all your domains, valid for a year. It saves it to the vault itself.

GitHub doesn't need a key in the vault

GitHub has its own sign-in flow for command-line tools. In chapter 6 the agent starts it, a browser window opens, you click Authorize. That's it. GitHub keeps that login in your computer's keychain.

Later keys

Two more things need a human, and they come up in their own chapters:

  • Google (chapter 11): you sign in once in the browser and accept Google's terms in Analytics and Tag Manager. The agent creates the actual key.
  • Stripe (chapter 10): Stripe needs to verify your business, so you create the account and copy one key into the vault.

Checklist

On a phone, swipe left and right to turn pages.